Exterior Paint Visualizer — Privacy Policy
Effective Date: August 24, 2026
Exterior Paint Visualizer ("the App") is developed by Mobile Card Games & Travel Apps LLC. This Privacy Policy explains what data the App collects, how it is used, and how your privacy is protected.
This policy covers both the iOS version, distributed through the Apple App Store, and the Android version, distributed through Google Play. The two versions behave the same way from your point of view, but they reach the image-generation service by different routes, so a few sections below distinguish between them. Where a section does not say otherwise, it applies to both.
1. Data We Collect
The App handles the following data:
- Home exterior photos: Photos of your home's exterior that you take with the camera or select from your photo library. To generate the repainted image, your photo is uploaded to OpenAI's image-generation service (see below).
- Paint color selections: The colors and exterior surfaces (siding, brick, trim, doors, shutters) you choose to repaint.
- Purchase information: Records of your in-app credit purchases, managed by Apple or Google Play together with RevenueCat.
- Anonymous account identifier (Android only): A randomly generated account ID, created without any sign-in, that holds your visualization credit balance. It is not linked to your name, email, or Google account.
- Device integrity and abuse-prevention signals: See section 3.
The App does not collect your name, email address, location, or device advertising identifiers, and contains no analytics or advertising SDKs.
2. How We Use Your Data
When you tap to visualize a paint color, your home exterior photo (resized and compressed) and a text description of the surfaces to repaint and the target color are sent to OpenAI's image-generation API (openai.com), which returns an edited image showing your home with the new paint color. In both versions the request travels over an encrypted HTTPS connection, and in neither version is the API key stored in the app itself.
On iOS
The request is relayed through AIProxy (aiproxy.com), a secure API relay service that holds the API key.
On Android
The request is relayed through our own backend, running on Google Cloud Functions in the United States, which holds the API key in Google Secret Manager and forwards the request to OpenAI. The backend also checks and updates your visualization credit balance. Your photo passes through this backend in memory only, for the duration of the request; it is never written to disk or to any storage bucket we operate.
Exterior photos may incidentally include people. Any such photo is treated exactly the same way: sent to OpenAI only to generate the repainted image, never analyzed for identity, and never stored on any server we operate. Per OpenAI's API data-usage policy, data sent through the API is not used to train their models.
3. Third-Party Data Sharing
- OpenAI (openai.com): Receives your home exterior photo and paint selections solely to generate the repainted image, over encrypted HTTPS.
- RevenueCat (revenuecat.com): Manages in-app credit purchases. RevenueCat receives purchase transaction tokens from Apple or Google Play and a random anonymous app-user ID — never your name, email, or photos. Payments themselves are processed by Apple or Google; we never see your payment card details.
- Google (firebase.google.com, Android only): Firebase provides the anonymous account, the credit ledger, and the abuse-prevention checks described below, and Google Play processes purchases and confirms them to our backend.
We do not sell, rent, or share your data with any other third parties.
Abuse prevention
Generating an image costs us money on every request, so both versions verify that requests come from a genuine installation of the App rather than a script.
- On iOS: each AI request includes your device's Apple identifier-for-vendor and an Apple DeviceCheck token.
- On Android: each request includes a Google Play Integrity attestation, obtained through Firebase App Check, which confirms the request comes from an unmodified copy of the App. Separately, when the App first contacts our backend it sends a one-way cryptographic hash of the Android device identifier, which lets us restore your credit balance after a reinstall and grant the one free visualization only once per device. We receive only the hash, never the identifier itself.
These signals are used solely to prevent abuse, restore purchases, and rate-limit AI requests. They are not linked to your name or identity and are not used for advertising or tracking.
4. Data Storage and Retention
- On your device: Original photos and generated results are stored locally on your device until you delete them from the App's history or uninstall the App.
- In your iCloud (iOS only): Your before/after history syncs across your devices via your private iCloud (CloudKit) database, tied to your Apple ID. This data is accessible only to you — we cannot access it. Your credit balance is synced via Apple iCloud key-value storage, which we also cannot access.
- On our servers (Android only): Because Android has no equivalent of the private iCloud database, the Android version keeps your credit balance on a server we operate, so that a reinstall or a new phone does not cost you credits you paid for. We store an anonymous account record containing your credit balance, the number of visualizations you have generated, the hashed device identifier described above, and a record of each purchase. We also keep a record of each visualization request — its anonymous account ID, timestamp, output size, and whether it succeeded — for 30 days, so that a failed generation can be refunded and abuse can be detected. These records never include your photos, your paint color choices, or the generated images. Your before/after history on Android stays on your device only.
- Photos: On neither platform do we operate any server that stores your photos. Photos exist in transit only, for the duration of the API request.
5. Data Security
All data transmitted to third-party services is sent over encrypted HTTPS connections. API keys are never embedded in the App: on iOS they are held by the AIProxy relay service, and on Android they are held in Google Secret Manager and used only by our backend. On Android, the credit balance can only be changed by our backend — the App itself has no write access to it — and every request to that backend must pass a Google Play Integrity check.
6. Your Rights
You have the right to:
- Delete individual before/after results from the App's history at any time.
- Remove all app data stored on your device by uninstalling the App. On iOS, iCloud-synced history can be removed by deleting items in the App before uninstalling.
- Deny camera or photo library permissions in iOS Settings or Android Settings, which prevents the App from accessing your photos.
- Request deletion of your anonymous account (Android): Because the Android account is anonymous, we cannot look it up by name or email. Email us at the address below from the device in question and we will tell you how to supply the account identifier shown in the App, then delete the account record and its associated data. Deleting the account also forfeits any unused visualization credits on it.
Depending on where you live, privacy laws such as the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) give you rights over your personal data, including the rights to know, access, correct, and delete it. On iOS we hold no data on servers we operate, so there is typically nothing for us to access or delete on request — deleting the App deletes your data. On Android, the anonymous account record described in section 4 is data we hold, and you may contact us at the email below to access or delete it. We will respond as required by applicable law.
7. Children's Privacy
The App is not directed at children under 13, and we do not knowingly collect data from children under 13. In some regions, including the European Union, a higher minimum age applies to consent for data processing; the same statement applies there — we do not knowingly collect data from anyone under the applicable age.
8. Data Breach Notification
In the unlikely event of a data breach affecting user data on any system we operate, we will notify affected users as required by applicable law.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Effective Date" at the top of this page.
10. Contact Us
If you have questions about this Privacy Policy or your data, please contact us at:
v5cqpsj4e3u4@opayq.com